NSFOCUS published research on the security implications of agent “SKILL/Skills” architectures used to package and orchestrate LLM capabilities (reasoning logic, tool calls, and execution flows) into reusable units. The write-up frames Skills as a growing ecosystem (claimed to exceed 100,000 units) that creates a new security boundary for authority management and execution control, and it highlights risk introduced by meta-tool-driven, on-demand prompt injection mechanisms used to load capabilities with low persistent context overhead. The paper positions the attack surface across architecture design, practical attack paths, and ecosystem-level exposure as Skills proliferate into AI IDEs and automated workflow scenarios.
A separate Gopher Security blog post discusses prompt-injection threats in Model Context Protocol (MCP) streams, arguing that encrypted orchestration channels can still be manipulated via indirect prompt injection (e.g., poisoning files/records the model consumes) and that defenders need behavioral/anomaly detection rather than relying on network trust boundaries. It also layers in speculative “quantum” framing (e.g., harvest now, decrypt later and future RSA/ECC risk) to motivate deeper inspection of MCP traffic without breaking privacy; while thematically adjacent (agent orchestration and prompt injection), it is not the same specific SKILL/Skills-architecture research described by NSFOCUS.

Track how attackers are adapting to this technology.
4 events from the most recent confirmed update back to the earliest known activity.
NSFOCUS recommended sourcing Skills only from trusted or official repositories, sandboxing agent execution environments, and conducting pre-deployment security reviews including static analysis, dynamic or semantic analysis, and dependency auditing. The guidance was aimed at reducing the risk of compromised or unsafe Skills being loaded by agents.
NSFOCUS Tianyuan Lab reported surveying roughly 700 open-source Skills from a broader ecosystem of more than 100,000 projects and found no in-the-wild poisoning cases in its sample. However, the lab identified multiple traditional security issues, with code-execution risks described as the most prevalent.
The research presented two practical cases: one in which malicious code embedded in a Skill script could trigger arbitrary command execution, and another in which a skill-creation workflow used Python eval in a way that enabled payload-based code execution despite superficial filtering. These examples showed how both malicious Skills and insecure Skill-generation tooling can lead to execution compromise.
NSFOCUS published research describing the security risks in LLM agent Skill architectures, highlighting supply-chain compromise and resource-poisoning threats arising from instruction files, scripts, and on-demand assets. The analysis emphasized that Skills create a new security boundary because agents may load poisoned prompts or execute compromised local code.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
nsfocusglobal.com
Open sourcensfocusglobal.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.